| Architecture |
IMAGE_FILE_MACHINE_I386
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2025-Dec-05 17:22:54 |
| Detected languages |
English - United States
|
| FileDescription | Wealth Resolution |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| LegalCopyright | Apt Pleasant Wealth Resolution 2018-2025 |
| ProductName | Wealth Resolution |
| CompanyName | Apt Pleasant Wealth Resolution |
| Info | Matching compiler(s): | Microsoft Visual C++ 6.0 - 8.0 |
| Suspicious | PEiD Signature: | Crunch/PE v5.0 |
| Info | Interesting strings found in the binary: |
Contains domain names:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to MD5
Uses constants related to SHA1 Uses constants related to AES Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE contains functions most legitimate programs don't use. |
[!] The program may be hiding some of its imports:
|
| Info | The PE is digitally signed. |
Signer: Bitcoin Futures LLC
Issuer: GlobalSign GCC R45 EV CodeSigning CA 2020 |
| Malicious | VirusTotal score: 4/72 (Scanned on 2026-02-04 13:09:01) |
DrWeb:
Adware.Downware.20796
Gridinsoft: Adware.Win32.SpecialSearchOffer.bot Malwarebytes: Adware.SpecialSearchOffer VBA32: BScope.RiskTool.DeceptPCClean |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x138 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_I386
|
| NumberofSections | 5 |
| TimeDateStamp | 2025-Dec-05 17:22:54 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xe0 |
| Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
|
| Magic | PE32 |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x3af400 |
| SizeOfInitializedData | 0x4cc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0031FCFE (Section: .text) |
| BaseOfCode | 0x1000 |
| BaseOfData | 0x3b1000 |
| ImageBase | 0x400000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x3ff000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x13e7c02 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
LoadLibraryExW
GlobalMemoryStatus GetCPInfo PeekNamedPipe DuplicateHandle SetFileTime TlsSetValue MoveFileExW InterlockedPushEntrySList TlsAlloc GetTempPathW GetVersion SetFilePointer SetEnvironmentVariableA CreateEventA GetFileAttributesA GetUserDefaultLCID CreateFileA FileTimeToSystemTime GetModuleHandleW CreateThread HeapReAlloc GetDateFormatW GetThreadPriority FindFirstFileW GetTickCount FreeEnvironmentStringsW GetVersionExW RemoveDirectoryA ReadFile FindClose TlsGetValue GetDriveTypeW CreateEventW GetTempFileNameW GetLocaleInfoW GetProcessHeap GetSystemTimeAsFileTime FreeLibraryAndExitThread RegisterWaitForSingleObject RaiseException CreateProcessA GetModuleHandleExW SetFilePointerEx GetModuleFileNameW IsValidCodePage VirtualAlloc FindNextFileW GetSystemInfo GetExitCodeThread EnterCriticalSection GetStringTypeW UnhandledExceptionFilter UnregisterWaitEx ReadConsoleW GetEnvironmentStringsW RtlUnwind WriteFile MultiByteToWideChar WaitForSingleObjectEx LCMapStringW GetCurrentProcessId GetTimeZoneInformation GetThreadTimes UnregisterWait LeaveCriticalSection ExitThread EnumSystemLocalesW GetTimeFormatW VirtualFree GetSystemDirectoryW DeleteCriticalSection DecodePointer FindFirstFileExA CreateDirectoryW FindFirstFileA InitializeCriticalSectionEx SetCurrentDirectoryW CreateTimerQueue TerminateProcess GetVersionExA AcquireSRWLockExclusive SystemTimeToTzSpecificLocalTime SetStdHandle CloseHandle IsProcessorFeaturePresent FormatMessageW GetProcessAffinityMask GetTempPathA DeleteTimerQueueTimer InitializeCriticalSection GetLastError SetEndOfFile GetFileAttributesW GetFileInformationByHandle EncodePointer SetLastError HeapSize GetOEMCP GetFileSize SetThreadAffinityMask InterlockedPopEntrySList GetFileType ExitProcess CreateDirectoryA LocalFree InitializeSListHead RemoveDirectoryW SetFileAttributesA SleepEx DeleteFileA CreateTimerQueueTimer TryEnterCriticalSection SetUnhandledExceptionFilter GetFileSizeEx SetFileAttributesW VerifyVersionInfoW FormatMessageA HeapAlloc GetConsoleMode GetCurrentProcess LoadLibraryW AreFileApisANSI GetModuleHandleA Sleep TlsFree SetThreadPriority IsValidLocale SetEvent GetFullPathNameW InterlockedFlushSList ReleaseSRWLockExclusive GetStartupInfoW GetLogicalProcessorInformation HeapFree GetEnvironmentVariableA GetCurrentThread SignalObjectAndWait WriteConsoleW GetModuleFileNameA SwitchToThread ResetEvent WaitForMultipleObjects VirtualProtect QueryDepthSList ReleaseSemaphore InitializeCriticalSectionAndSpinCount GetCurrentThreadId CreateSemaphoreA DeleteFileW FlushFileBuffers SetCurrentDirectoryA CreateFileW GetCommandLineA CompareStringW ChangeTimerQueueTimer WideCharToMultiByte QueryPerformanceCounter GetConsoleCP FreeLibrary GetCommandLineW GetCurrentDirectoryW GetStdHandle FindNextFileA GetNumaHighestNodeNumber IsDebuggerPresent GetFileAttributesExW QueryPerformanceFrequency GetProcAddress WaitForSingleObject GetCurrentDirectoryA GetACP VerSetConditionMask |
|---|---|
| USER32.dll |
GetDlgItem
PostMessageA DialogBoxParamW LoadStringA CharUpperW MessageBoxW CharUpperA SetTimer LoadStringW DestroyWindow KillTimer SetWindowTextW GetWindowLongA SetWindowLongA DialogBoxParamA SendMessageA SetWindowTextA LoadIconA ShowWindow EndDialog |
| SHELL32.dll |
ShellExecuteExA
|
| OLEAUT32.dll |
VariantClear
SysStringLen SysAllocStringLen |
| bcrypt.dll |
BCryptGenRandom
|
| ADVAPI32.dll |
CryptReleaseContext
CryptEncrypt CryptDestroyHash CryptCreateHash CryptGetHashParam CryptHashData CryptAcquireContextW CryptDestroyKey CryptImportKey |
| Ordinal | 1 |
|---|---|
| Address | 0x305ae0 |
| Extraction Failed |
| File is corrupt |
| Cannot create folder '{0}' |
| Extracting |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 1.0.0.0 |
| ProductVersion | 1.0.0.0 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_APP
|
| Language | English - United States |
| FileDescription | Wealth Resolution |
| FileVersion (#2) | 1.0.0.0 |
| ProductVersion (#2) | 1.0.0.0 |
| LegalCopyright | Apt Pleasant Wealth Resolution 2018-2025 |
| ProductName | Wealth Resolution |
| CompanyName | Apt Pleasant Wealth Resolution |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2025-Dec-05 17:22:54 |
| Version | 0.0 |
| SizeofData | 844 |
| AddressOfRawData | 0x3ddf5c |
| PointerToRawData | 0x3dc75c |
| Size | 0xa0 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x7e6034 |
| SEHandlerTable | 0x7ddac0 |
| SEHandlerCount | 295 |
| XOR Key | 0xa4b4acb2 |
|---|---|
| Unmarked objects | 0 |
| Imports (23907) | 2 |
| ASM objects (23907) | 1 |
| C++ objects (23907) | 17 |
| C objects (23907) | 10 |
| Imports (VS2015 UPD2 build 23918) | 2 |
| Imports (VS2017 v15.5.2 compiler 25831) | 2 |
| Imports (VS2008 SP1 build 30729) | 15 |
| Total imports | 207 |
| C++ objects (VS2015 UPD2 build 23918) | 1 |
| Resource objects (VS2015 UPD2 build 23918) | 1 |
| Linker (VS2015 UPD2 build 23918) | 1 |